Writing application policy
Illumio allows or denies traffic between applications using policies that you write. For an overview of the Illumio Segmentation for the Cloud policy model, see About the Policy Model.
For a list of resources against which you can write policy, see Policy enforcement and resource types.
In order to write application policies, you must create rules for the policy. Illumio Segmentation for the Cloud has the following types of rules for application policies:
This topic provides an overview of using rules to write Illumio Segmentation for the Cloud policies. For instructions on creating rules for policies, see the in-application help.
Differences between application and organization policies
You can think of application policies as segmentation policies to control network traffic using Illumio labels, services, and IP/IP lists to define what can talk to applications. The guidelines below are generally applicable to writing both organization and application policies. For differences, see Organization policy versus application policy.
Guidelines
Use the following guidelines when creating rules for your policies:
From the Source and Destination drop-down lists, you can select a combination of applications, labels, and IP lists. Note that when programming security groups, Illumio Segmentation for the Cloud optimizes the rules by grouping a set of IPs into a CIDR block if possible.
From the Destination Services drop-down list, you can select a combination of services and ports. Note that when there are adjacent rules i.e., adjacent ports, with all other parameters same, Illumio Segmentation for the Cloud merges those rules. For example if you have Rule1 (ports 87100-87104), Rule2 (ports 87105), Rule3 (ports 87106-87110), then CS combines those rules to program a single rule with the port range 87100-87110.
In the source or destination fields, select All Resources to include all resources at once instead of selecting them individually. By using All Resources in your source or destination, you can write organization policies for all resources in onboarded cloud accounts.
The UI will prevent you from selecting disallowed source and destination combinations. For a full list of permitted source and destination combinations in a rule, see Permitted rule writing combinations.
After completing your selections, click the Save icon at the end of the row for that rule
To edit a rule, click the Edit icon at the end of the row
After adding a rule, the Status column displays a green Enabled icon and the Provision Status column displays a green Pending icon
Rules can be disabled or removed individually or in groups by selecting the check box next to a rule
To enforce a rule, you must provision the policy. For more information about provisioning, see Provisioning.
Reverting a policy from the Applications > your policy name > Policy tab will cancel pending changes to the policy, including rules with a green Pending icon in the Provision Status column, and revert to the previously provisioned policy
From the left navigation Policies menu item, reverting a policy that still has its provisioning pending will cancel that provisioning but leave previously saved policy rules intact
Permitted rule writing combinations
Inter-application and inter-deployment policy
Illumio allows you to write rules between your applications and between your deployments. However, in order to write these rules, rules must be written in the context of the application on the inbound side of the rules. In other words, you can only write inbound inter-application and inter-deployment policy rules. However, when you do so, Illumio Segmentation for the Cloud implicitly writes outbound rules for the security group containing the source application. This is to avoid the need for you or the security group owner to explicitly write a corresponding outbound rule.
Under a given application, if you want to specify an application in the destination of the rule, the application must match the application in the context. So, the destination application must be the application in which you are writing the rule. The source application can be a different application (or the same) than the application context in which you are writing the policy.
If a deployment is specified, the same principal applies to the destination deployment. You can write the rule for only the deployment context in which you are writing the policy. The source deployment can be a different deployment (or the same) than the application context in which you are writing the policy.
Note
If the source does not match the application or deployment context, Illumio Segmentation for the Cloud will take the meaning of the labels literally. For example, if the context is app:CRM, deployment:PROD, a rule with the source as app:FINANCE will represent all resources under app:FINANCE, regardless of deployment. This is true of all rule types (allow, deny, etc.).
If Source is | And Service is | Destination can be |
|---|---|---|
Application and/or deployment (any) | Any service | The application and/or deployment (if applicable), so long as it is the same as the one providing the context |
IP List | Any service | Application or label |
Intra-application and intra-deployment policy
In order to write rules within your application context, you can specify labels or IP lists on either side of the rule.
Note
These labels must not be of the application or deployment types in order for the following to apply.
If a label is used on either side of the rule, Illumio Segmentation for the Cloud will calculate which resources match both the context (application and/or deployment) and the label used, and create the rule accordingly.
If Source is | And service is | Destination can be |
|---|---|---|
Any label or IP list | Any service | Any label or IP list |
Provisioning
When you provision updates, Illumio Segmentation for the Cloud recalculates any changes made to rules, and then transmits those changes to all affected enforcement points. All the changes you make to those rules are considered to be in a “draft” state until you provision them.
Previewing the Impact of Provisioning a Policy
This section provides an overview of the Show Impact feature. For instructions on previewing policy impact, see the in-application help.
Before you provision a policy, consider previewing what its impact will be when it's provisioned. This can help you gauge how the policy will map to destinations, security group rules, enforcement points, and so forth.
To see such mappings on a policy that has not yet been provisioned, click Show Impact. You can then choose one of the following security controls from the drop-down menu:
All security controls
Azure NSGs
AWS Security Groups
Network Access Control Lists
Azure Firewall Policies
GCP Firewall Rules
Each of these show you the following:
CSP
Resource
Account ID
Number of Protected Resources
Rules
If you select any particular affected AWS SG, AWS NACL, Azure NSG, or Azure Firewall, you may see rules that come from other applications and/or policies. Note that only Illumio-written rules will display. The draft change summary will include the account name, as well as inbound and outbound rules with the following details :
Provision Status (this can tell you whether a rule is being added, removed, or is already in place)
Source
Destination
Port
Protocol
Action (deny, override deny, or allow)
Confirming
Once you have previewed the anticipated impact, you are ready to decide whether to proceed with provisioning.
You are given a description field for adding any comments when provisioning a policy. After you provision your changes, those changes become “active,” which is to say it is in enforcement mode. When you confirm by clicking Confirm & Provision, the Policies page Provision Status column displays the applications with policies, including those that are pending.
Review provisioning results and errors
Limited Availability
Currently, this feature is accessible to only a limited number of organizations.
After you provision a policy, review the provision results to confirm which security controls received the policy changes and identify any controls that require attention. On the policy page, click the provisioning details icon for a rule to open its Provision Details.
Provision Details provides an overview of the security controls affected by the rule. It shows the number of controls that were successfully provisioned and the number that failed. Select View All Security Controls to review the results for individual controls.
On the Security Controls page, filter the results by account, resource group, status, or issue type.
Use Provisioned status to view controls where the policy was successfully applied.
Use Provisioning Failed to view controls where the policy could not be applied.
The results include the security control, account ID, resource group, provisioning status, and issue type.
Resolve provisioning errors
To investigate a failed provisioning attempt, open Provision Details and expand an error category:
Permission Denied
The cloud account or service identity that Illumio uses lacks the permissions required to create, modify, or delete the affected security controls. Missing IAM roles or actions, restrictive scope assignments, service control policies, Azure Policy definitions, organization policies, or similar access controls can cause this error.
Quota Reached
The affected cloud resource has reached its configured or platform-defined limit for rules, entries, capacity, or related objects. Illumio cannot provision additional policy objects until you remove or consolidate unused rules, recreate the resource with greater capacity where applicable, or request a quota increase from the cloud provider.
Resource Locked
A user or policy has applied a lock or equivalent protection to the affected cloud resource or one of its parent scopes. The lock prevents Illumio from modifying or deleting the resource. Remove the lock temporarily or permanently, or use an approved exception or change process to complete provisioning.
Internal Error
Illumio encountered an unexpected internal failure while processing or provisioning the requested policy change. The available information does not identify a confirmed cloud permission, quota, or resource-lock issue. Verify the cloud resource and integration status, then retry the operation. If the error persists, collect the error details, affected resource identifiers, timestamps, and relevant logs, and escalate the issue to Illumio Support or the responsible internal team.
The expanded error includes the issue owner and a recommended action when available. For example, a permission error might instruct the cloud administrator to grant the required IAM permissions to the CloudSecure service role.
From the Provision Details page, review accounts and security controls affected by each error. Select Details for a security control to view its provisioning result. Where available, select Remediate to address the issue. After resolving the underlying cloud configuration or permission issue, provision the policy again and verify that the affected controls show a Provisioned status.
Reprovision
After addressing provisioning errors, click Reprovision to retry provisioning. Clicking this triggers 10 consecutive provisioning attempts.
Application policy caveats
Only rules that use the following attributes are supported:
Applications, labels, IP lists, and services
As AWS does not have a deny rule concept for Security Groups, an Illumio override deny rule will only be implemented if there is a matching allow rule that is overlapping in scope. In effect, the override deny rule will constrict where the allow rule is implemented.
You cannot write policy rules using metadata, but you can map cloud tags to Illumio labels and then write policy rules using that label
Only the following ServiceCategory labels can be used when authoring policy: Compute, Serverless, and Network Management. ServiceRole labels can also be used when authoring policy, but the service roles must have resources that support policy.